---
id: CVE-2026-0289
title: "A  security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables\_a user to bypass intended security controls."
summary: "A  security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables\_a user to bypass intended security controls."
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-522
vendor: paloaltonetworks
product: prisma_browser
affected:
  - prisma_browser < 150.49.4.125
patched:
  - prisma_browser 150.49.4.125
published: '2026-08-13'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:15:04.617'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0289'
references:
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0289'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
  - cve.org
  - score-dispute
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-13T13:17:29.230433Z'
scores:
  nvd: 6.5
  cna: 0.5
ingestedAt: '2026-09-13T09:26:55.426Z'
epss: 0.00225
epssPercentile: 0.11741
---

## Overview

A  security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.

## Affected

- `prisma_browser < 150.49.4.125`

## Remediation

Upgrade past the affected range:

- `prisma_browser 150.49.4.125`
